Error with IIS Native SP

Boyd, Todd M. tmboyd1 at ccis.edu
Mon Sep 25 14:48:21 EDT 2017


If I take out the one MetadataProvider element in the IdP metadata configuration XML that points to this problematic SP, everything runs fine. If I add it back in, I get the errors. The metadata is being generated automatically by the SP, as far as I can tell. I'll certainly attach both, though:

IdP's metadata configuration:

<?xml version="1.0" encoding="UTF-8"?>
<MetadataProvider id="ShibbolethMetadata" xsi:type="ChainingMetadataProvider"
	xmlns="urn:mace:shibboleth:2.0:metadata"
	xmlns:resource="urn:mace:shibboleth:2.0:resource"
	xmlns:security="urn:mace:shibboleth:2.0:security"
	xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xsi:schemaLocation="urn:mace:shibboleth:2.0:metadata http://shibboleth.net/schema/idp/shibboleth-metadata.xsd
		urn:mace:shibboleth:2.0:resource http://shibboleth.net/schema/idp/shibboleth-resource.xsd
		urn:mace:shibboleth:2.0:security http://shibboleth.net/schema/idp/shibboleth-security.xsd
		urn:oasis:names:tc:SAML:2.0:metadata http://docs.oasis-open.org/security/saml/v2.0/saml-schema-metadata-2.0.xsd">
	<MetadataProvider id="adfs.ccis.edu"
		xsi:type="FileBackedHTTPMetadataProvider"
		backingFile="%{idp.home}/metadata/adfs.ccis.edu.xml"
		metadataURL="https://adfs.ccis.edu/FederationMetadata/2007-06/FederationMetadata.xml" />
	<!-- this one's the problem -->
	<MetadataProvider id="tmb_test"
		xsi:type="FileBackedHTTPMetadataProvider"
		backingFile="%{idp.home}/metadata/d100hmd2.ccis.edu.xml"
		metadataURL="https://d100hmd2.ccis.edu/Shibboleth.sso/Metadata" />
</MetadataProvider>


SP's metadata configuration:

<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_49f1a94464b14e84a6a573a80857c59dfd14fc47" entityID="https://d100hmd2.ccis.edu/shibboleth">
  <md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport">
    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
    <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
  </md:Extensions>
  <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
    <md:Extensions>
      <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/Login"/>
      <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/Login" index="1"/>
    </md:Extensions>
    <md:KeyDescriptor>
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:KeyName>d100hmd2.ccis.edu</ds:KeyName>
        <ds:X509Data>
          <ds:X509SubjectName>CN=d100hmd2.ccis.edu</ds:X509SubjectName>
          <ds:X509Certificate>MIID+jCCAmKgAwIBAgIJAI8h2JxMStu1MA0GCSqGSIb3DQEBCwUAMBwxGjAYBgNV
BAMTEWQxMDBobWQyLmNjaXMuZWR1MB4XDTE3MDkyNTE1Mjc1N1oXDTI3MDkyMzE1
Mjc1N1owHDEaMBgGA1UEAxMRZDEwMGhtZDIuY2Npcy5lZHUwggGiMA0GCSqGSIb3
DQEBAQUAA4IBjwAwggGKAoIBgQC92K9F6ns9LD6aQWoc769DnAMX/U+3n+IGs1P+
1wkmW5XEo9YlXeBd/6bAuk0U++TyqDjOvVzJ68LGsaXu4rH0RKYfDil+qcd0DKye
cEQyDuUw4E9bG4ZnXKFcmg7Coj/YQ8aH9vjpBkYyOeKtAaOdYfj6RAoPr1ePU9NE
r8o36CmLooNai8JjCXLa34HR3e33Ap8yx5JsdwAHdxirWbK1LRMxF3+z7bWIqKWE
i/ffoH0AyBsACkur9u0rhM2fSoU39Rg4txhEhC5LPD60dh1rNcAlGP1tTdsTtjP6
T4gLYOrFZVzcB/GIhYgkDOnsi4r8qjt0KPI6c8JozgHwbNs5lc/kA6Rtr7r/olYO
PVJyyXxcileztHM75pskkwKaPeglbjFQki4K/Ze5Z/VavCEs+WMOYbMH/pptLWIH
j3QsZamZOh6CrZP8cjSEtUUIUsV5WsEGCeG8me58lrZbyWuDp1vSxNMMHR+xMGoR
PjJKGs2F863o0gDVzflrnBxqkEsCAwEAAaM/MD0wHAYDVR0RBBUwE4IRZDEwMGht
ZDIuY2Npcy5lZHUwHQYDVR0OBBYEFMGpQFxd/Ew0Su8FGK0tIuumg6JWMA0GCSqG
SIb3DQEBCwUAA4IBgQANHbPv+bVCHp0dAL7OyCodmbjyrdTubAlgQTnitSc6io4a
WX4z+b7Bn/1HtImIXCmPXPYEe5XTVcTYzshL+VWjkKOyof2qX+HebI1Nm+nAOBVZ
Nkt5FMDzZZCLDvTR3eFQloGaI7pdHk6RiXtU+2DymRv6xiVOKnURXMJC61sLPB9Q
94jfoKNE2OTiCaKZ5wlDhATloKibQqucXcEdwI7aziQbVQ/faQnuKEhC69IVlgHH
3RW2FjNW9Yzw3mpyOSMZjJiNretfG+MLY7g7wO4FM3kbOwgAiyP/iT+4wb4ss/Qc
IVFem5EfrmsXVJkXXKmxcwJOFC1UsfLtw6iH4O2Rdr1zmIZmA7BJf7pxI8gVGhOf
AABJXwK4Zu/pwm4j8hQEsxE3U37VcBd4YXQqVF2iEDliDlKeATauSKkeCMg2Y0sx
DjzyZ7wWJ6sb8imvNckX2/Yc05QvlAlqW7V1wi8igFv12PBfkmtMsEaVpDVRA5it
9mpruvTfRcUJXF+T7PY=
</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
    </md:KeyDescriptor>
    <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/Artifact/SOAP" index="1"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SLO/SOAP"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SLO/Redirect"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SLO/POST"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SLO/Artifact"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SAML2/POST" index="1"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SAML2/Artifact" index="3"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SAML2/ECP" index="4"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SAML/POST" index="5"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://d100hmd2.ccis.edu/Shibboleth.sso/SAML/Artifact" index="6"/>
  </md:SPSSODescriptor>
</md:EntityDescriptor>


-Todd


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Peter Schober
Sent: Monday, September 25, 2017 1:40 PM
To: users at shibboleth.net
Subject: Re: Error with IIS Native SP

* Boyd, Todd M. <tmboyd1 at ccis.edu> [2017-09-25 19:54]:
> Looking in the debug logs for the IdP, I see this:
> 
> org.springframework.expression.spel.SpelEvaluationException:
> EL1008E:(pos 0): Property or field 'ShibServerName' cannot be found on 
> object of type 
> 'org.springframework.beans.factory.config.BeanExpressionContext' - 
> maybe not public?

No idea but the fact that it mentions
"shibboleth.UnverifiedRelyingParty" doesn't look good if you fed metadata about the SP to the IDP (i.e., it should be "unverified", then).

So obviously the IDP is misconfigured, maybe you fed it something other than SAML 2.0 Metadata describing the SP?

You could share your IDP metadata configuration and the SP metadata referenced therein, -peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list